The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring SMTP settings

Prev Next

To configure the SMTP settings, perform the following subtasks:

  • Specify the SMTP server.

  • Set the default SMTP notification settings.

  • (Optional) Set authentication for SMTP notification settings.

  • (Optional) Set preferences for SMTP notifications.

To specify which SMTP server to use:
  1. Go to CLI configuration mode:

    hostname > enable

    hostname # configure terminal

  2. Enable email notifications:

    hostname (config) # fenotify email enable

  3. Set the mail port used to send the email notifications:

    hostname (config) # fenotify email mailhub port <port-number>

  4. Save the configuration.

    hostname (config) # write memory

To configure the default settings for SMTP notifications:
  1. Go to CLI configuration mode:

    hostname > enable

    hostname # configure terminal

  2. Enable email notifications:

    hostname (config) # fenotify email enable

  3. Set the domain from which emails appear to come:

    hostname (config) # fenotify email domain <email-domain>

  4. (Optional) To include the hostname in the return address for email notifications:

    hostname (config) # fenotify email return host-name <host_name>

  5. Set the user name in the return address for email notifications (the default is do-not-reply):

    hostname (config) # fenotify email return user-name <user_name>

  6. Select one of the XML, JavaScript Object Notation (JSON), or Text options for the default format of the notification:

    Note

    The json_legacy-concise, json_legacy-extended, and json_legacy-normal formats are deprecated.

    • To send notifications in XML Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:

      hostname (config) # fenotify email default format xml-concise

    • To send notifications in XML Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (XML Extended provides all details about files and objects modified during analysis.), enter:

      hostname (config) # fenotify email default format xml-extended

    • To send notifications in XML Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:

      hostname (config) # fenotify email default format xml-normal

    • To send notifications in JSON Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:

      hostname (config) # fenotify email default format json-concise

    • To send notifications in JSON Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (JSON Extended provides all details about files and objects modified during analysis.), enter:

      hostname (config) # fenotify email default format json-extended

    • To send notifications in JSON Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:

      hostname (config) # fenotify email default format json-normal

    • To send notifications in Text Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:

      hostname (config) # fenotify email default format text-concise

    • To send notifications in Text Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (Text Extended provides all details about files and objects modified during analysis.), enter:

      hostname (config) # fenotify email default format text-extended

    • To send notifications in Text Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:

      hostname (config) # fenotify email default format text-normal

  7. Specify how the notification is delivered by default:

    • To deliver the notification as an email attachment, enter:

      hostname (config) # fenotify email default send-as attachment

    • To deliver the notification in the email body (the default), enter:

      hostname (config) # fenotify email default send-as in-line

  8. Specify the default delivery schedule for email notifications:

    Note

    Trellix recommends using per-event notifications.

    • To receive information about all events detected in the past 24 hours, enter:

      hostname (config) # fenotify email default delivery daily-digest

    • To receive a daily notification for each entity that was the source of the event, enter:

      hostname (config) # fenotify email default delivery daily-per-source

    • To receive an hourly notification for each entity that was the source of the event, enter:

      hostname (config) # fenotify email default delivery hourly-per-source

    • To receive a notification every minute for each entity that was the source of the event, enter:

      hostname (config) # fenotify email default delivery per-1min-per-source

    • To receive a notification every 5 minutes for each entity that was the source of the event, enter:

      hostname (config) # fenotify email default delivery per-5min-per-source

    • To receive information about each event, sent when the event is triggered, enter:

      hostname (config) # fenotify email default delivery per-event

  9. Save the configuration:

    hostname (config) # write memory

To configure authentication for SMTP notifications:
  1. Go to CLI configuration mode:

    hostname > enable

    hostname # configure terminal

  2. Enable email notifications:

    hostname (config) # fenotify email enable

  3. Enable authentication for event mail notifications:

    hostname (config) # fenotify email mailhub auth enable

  4. Set the authentication method you want to use to send event mail notifications. Available methods include PLAIN, LOGIN, or CRAM-MD5.

    hostname (config) # fenotify email mailhub auth auth-method PLAIN

  5. Set the username required to authenticate sending event email notifications:

    hostname (config) # fenotify email mailhub auth username <username>

  6. Set the password required to authenticate sending event email notifications:

    hostname (config) # fenotify email mailhub auth password <password>

To configure preferences for SMTP notifications:
  1. Go to CLI configuration mode:

    hostname > enable

    hostname # configure terminal

  2. Enable email notifications:

    hostname (config) # fenotify email enable

  3. Enable From: line override for event mail notifications:

    hostname (config) # fenotify email mailhub preferences from-line-override enable

  4. Set the minimum SSL protocol version required to send event mail notifications through SMTP. The following versions are supported:

    • ssl3: SSLv3 or higher is required.

    • tls1: TLSv1 or higher is required.

    • tls1.1: TLSv1.1 or higher is required.

    • tls1.2: TLSv1.2 or higher is required.

    hostname (config) # fenotify email mailhub preferences ssl-min-version <ssl-min-version>

  5. (Optional) Set the TLS certificate authority file for event mail notifications going through SMTP. You can choose filenames under the /etc/pki/tls/certs/ directory.

    hostname (config) # fenotify email mailhub preferences tls-ca-file <tls-ca-file>

    The following example sets the TLS certificate authority file for event mail notifications to ca-bundle.crt:

    hostname (config) # fenotify email mailhub preferences tls-ca-file <ca-bundle.crt>

  6. (Optional) Set the TLS certificate file for event email notifications going through SMTP. You can choose filenames under the /etc/pki/tls/ directory.

    hostname (config) # fenotify email mailhub preferences tls-cert-file <tls-cert-file>

    The following example sets the TLS certificate file for event mail notifications to cert.pem:

    hostname (config) # fenotify email mailhub preferences tls-cert-file <cert.pem>